You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/role-based-access-control/built-in-roles.md
+38-31Lines changed: 38 additions & 31 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.devlang:
12
12
ms.topic: reference
13
13
ms.tgt_pltfrm:
14
14
ms.workload: identity
15
-
ms.date: 02/18/2020
15
+
ms.date: 03/12/2020
16
16
ms.author: rolyon
17
17
ms.reviewer: bagovind
18
18
@@ -73,14 +73,14 @@ The following table provides a brief description and the unique ID of each built
73
73
> |[Blockchain Member Node Access (Preview)](#blockchain-member-node-access-preview)| Allows for access to Blockchain Member nodes | 31a002a1-acaf-453e-8a5b-297c9ca1ea24 |
74
74
> |[Blueprint Contributor](#blueprint-contributor)| Can manage blueprint definitions, but not assign them. | 41077137-e803-4205-871c-5a86e6a753b4 |
75
75
> |[Blueprint Operator](#blueprint-operator)| Can assign existing published blueprints, but cannot create new blueprints. NOTE: this only works if the assignment is done with a user-assigned managed identity. | 437d2ced-4a38-4302-8479-ed2bcb43d090 |
76
-
> |[CDN Endpoint Contributor](#cdn-endpoint-contributor)| Can manage CDN endpoints, but can’t grant access to other users. | 426e0c7f-0c7e-4658-b36f-ff54d6c29b45 |
77
-
> |[CDN Endpoint Reader](#cdn-endpoint-reader)| Can view CDN endpoints, but can’t make changes. | 871e35f6-b5c1-49cc-a043-bde969a0f2cd |
78
-
> |[CDN Profile Contributor](#cdn-profile-contributor)| Can manage CDN profiles and their endpoints, but can’t grant access to other users. | ec156ff8-a8d1-4d15-830c-5b80698ca432 |
79
-
> |[CDN Profile Reader](#cdn-profile-reader)| Can view CDN profiles and their endpoints, but can’t make changes. | 8f96442b-4075-438f-813d-ad51ab4019af |
76
+
> |[CDN Endpoint Contributor](#cdn-endpoint-contributor)| Can manage CDN endpoints, but can't grant access to other users. | 426e0c7f-0c7e-4658-b36f-ff54d6c29b45 |
77
+
> |[CDN Endpoint Reader](#cdn-endpoint-reader)| Can view CDN endpoints, but can't make changes. | 871e35f6-b5c1-49cc-a043-bde969a0f2cd |
78
+
> |[CDN Profile Contributor](#cdn-profile-contributor)| Can manage CDN profiles and their endpoints, but can't grant access to other users. | ec156ff8-a8d1-4d15-830c-5b80698ca432 |
79
+
> |[CDN Profile Reader](#cdn-profile-reader)| Can view CDN profiles and their endpoints, but can't make changes. | 8f96442b-4075-438f-813d-ad51ab4019af |
80
80
> |[Classic Network Contributor](#classic-network-contributor)| Lets you manage classic networks, but not access to them. | b34d265f-36f7-4a0d-a4d4-e158ca92e90f |
81
81
> |[Classic Storage Account Contributor](#classic-storage-account-contributor)| Lets you manage classic storage accounts, but not access to them. | 86e8f5dc-a6e9-4c67-9d15-de283e8eac25 |
82
82
> |[Classic Storage Account Key Operator Service Role](#classic-storage-account-key-operator-service-role)| Classic Storage Account Key Operators are allowed to list and regenerate keys on Classic Storage Accounts | 985d6b00-f706-48f5-a6fe-d0ca12fb668d |
83
-
> |[Classic Virtual Machine Contributor](#classic-virtual-machine-contributor)| Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they’re connected to. | d73bb868-a0df-4d4d-bd69-98a00b01fccb |
83
+
> |[Classic Virtual Machine Contributor](#classic-virtual-machine-contributor)| Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they're connected to. | d73bb868-a0df-4d4d-bd69-98a00b01fccb |
84
84
> |[Cognitive Services Contributor](#cognitive-services-contributor)| Lets you create, read, update, delete and manage keys of Cognitive Services. | 25fbc0a9-bd7c-42a3-aa1a-3b75d497ee68 |
85
85
> |[Cognitive Services Data Reader (Preview)](#cognitive-services-data-reader-preview)| Lets you read Cognitive Services data. | b59867f0-fa02-499b-be73-45a86b5b3e1c |
86
86
> |[Cognitive Services User](#cognitive-services-user)| Lets you read and list keys of Cognitive Services. | a97b65f3-24c7-4388-baec-2e87135dc908 |
@@ -141,7 +141,7 @@ The following table provides a brief description and the unique ID of each built
141
141
> |[Spatial Anchors Account Owner](#spatial-anchors-account-owner)| Lets you manage spatial anchors in your account, including deleting them | 70bbe301-9835-447d-afdd-19eb3167307c |
142
142
> |[Spatial Anchors Account Reader](#spatial-anchors-account-reader)| Lets you locate and read properties of spatial anchors in your account | 5d51204f-eb77-4b1c-b86a-2ec626c49413 |
143
143
> |[SQL DB Contributor](#sql-db-contributor)| Lets you manage SQL databases, but not access to them. Also, you can't manage their security-related policies or their parent SQL servers. | 9b7fa17d-e63e-47b0-bb0a-15c516ac86ec |
144
-
> |[SQL Managed Instance Contributor](#sql-managed-instance-contributor)| Lets you manage SQL Managed Instances and required network configuration, but can’t give access to others. | 4939a1f6-9ae0-4e48-a1e0-f2cbe897382d |
144
+
> |[SQL Managed Instance Contributor](#sql-managed-instance-contributor)| Lets you manage SQL Managed Instances and required network configuration, but can't give access to others. | 4939a1f6-9ae0-4e48-a1e0-f2cbe897382d |
145
145
> |[SQL Security Manager](#sql-security-manager)| Lets you manage the security-related policies of SQL servers and databases, but not access to them. | 056cd41c-7e88-42e1-933e-88ba6a50c9c3 |
146
146
> |[SQL Server Contributor](#sql-server-contributor)| Lets you manage SQL servers and databases, but not access to them, and not their security -related policies. | 6d8ee4ec-f05a-4a1d-8b00-a9b17e38b437 |
147
147
> |[Storage Account Contributor](#storage-account-contributor)| Permits management of storage accounts. Provides access to the account key, which can be used to access data via Shared Key authorization. | 17d1049b-9a84-46fb-8f53-869881c3d3ab |
@@ -1020,7 +1020,7 @@ Allows for access to Blockchain Member nodes
1020
1020
1021
1021
### Classic Virtual Machine Contributor
1022
1022
1023
-
Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they’re connected to.
1023
+
Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they're connected to.
1024
1024
1025
1025
> [!div class="mx-tableFixed"]
1026
1026
> |||
@@ -1055,7 +1055,7 @@ Lets you manage classic virtual machines, but not access to them, and not the vi
1055
1055
"assignableScopes": [
1056
1056
"/"
1057
1057
],
1058
-
"description": "Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they’re connected to.",
1058
+
"description": "Lets you manage classic virtual machines, but not access to them, and not the virtual network or storage account they're connected to.",
@@ -3849,10 +3849,7 @@ Can manage blueprint definitions, but not assign them.
3849
3849
3850
3850
### Blueprint Operator
3851
3851
3852
-
Can assign existing published blueprints, but cannot create new blueprints.
3853
-
3854
-
> [!NOTE]
3855
-
> This works only if the assignment is done with a user-assigned managed identity.
3852
+
Can assign existing published blueprints, but cannot create new blueprints. NOTE: this only works if the assignment is done with a user-assigned managed identity.
3856
3853
3857
3854
> [!div class="mx-tableFixed"]
3858
3855
> |||
@@ -4312,6 +4309,8 @@ Can read all monitoring data and edit monitoring settings. See also [Get started
0 commit comments